Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Centos:7 python-libs to version 0:2.7.5-34.el7 or higher.
Note: Versions mentioned in the description apply only to the upstream python-libs package and not the python-libs package as distributed by Centos.
See How to fix? for Centos:7 relevant fixed versions and status.
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.